
CiscoCertified Support Technician (CCST) Cybersecurity
Domain 5Objective 1
Monitor Security Events and Know When Escalation Is Required 100-160 Practice Questions (Page 1)
Part of the Incident Handling domain, which makes up ~18% of our current practice bank. Cisco does not publish an official question count, but from its 50-minute exam (~20–35 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
6concepts
Questions 1–5
- 1
A SOC uses a SOAR platform to handle phishing alerts. When a phishing email is reported, the SOAR automatically extracts indicators, checks them against threat intelligence, and quarantines the email if the indicators are malicious. The SOC manager wants to ensure that a human reviews every quarantine action. What should the manager configure?
Select an answer first - 2
A company has a SIEM that ingests NetFlow data from its core router and Windows Event Logs from its domain controllers. The security team is investigating a potential data exfiltration. They notice that a workstation has been sending large amounts of data to an external IP address. The NetFlow data shows the traffic, but the team needs to determine if the data contained sensitive files. The Windows Event Logs do not show any file access events for the workstation. What is the most significant limitation of the current monitoring setup?
Select an answer first - 3
A network analyst is investigating a potential data exfiltration. The analyst needs to see the actual content of the traffic between an internal host and an external server to determine if sensitive data was sent. Which data source should the analyst use?
Select an answer first - 4
A SOC analyst sees an alert for a single failed login on a domain controller, followed by a successful login from the same IP address. The user is a standard employee. The analyst checks the SIEM and finds no other related events. What should the analyst do?
Select an answer first - 5
A security analyst reviews a Windows security log and sees multiple failed logon events for the same user account within a short time, followed by a successful logon. Which type of activity does this pattern most likely indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “100-160” is a trademark of its owner, used for identification only.